Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
All types
CVE only
Pre-CVE only
CISA KEV only
All severities
Critical
High
Medium
Low
More filters
Trending
Newest
Urgent
Critical Only
Weekly Urgent
Weekly Trending
165,587 vulnerabilities total
10.0
cis ·
CVE-2026-20127 —
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
KEV
EXPLOITED
PATCHED
catalyst_sd-wan_manager
· CVSS 10.0
· CWE-287
120
🔥
17 art.
0
Feb 25, 2026
7.8
linux ·
CVE-2026-31431 —
crypto: algif_aead - Revert to operating out-of-place
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
117
🔥
84 art.
0
Apr 22, 2026
8.8
linux ·
CVE-2026-43284 —
xfrm: esp: avoid in-place decrypt on shared skb frags
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 8.8
112
🔥
41 art.
0
May 8, 2026
7.8
linux ·
CVE-2026-43500 —
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
106
🔥
28 art.
0
May 11, 2026
10.0
ui ·
CVE-2026-34908 —
CVE-2026-34908: A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de
KEV
EXPLOITED
PATCHED
unifi_os_server
· CVSS 10.0
· CWE-284
97
9 art.
0
May 22, 2026
—
ptc ·
CVE-2026-12569 —
Remote Code Execution (RCE) vulnerability in Windchill PDMlink
EXPLOITED
PATCHED
flexplm
· CWE-20
96
8 art.
0
Jun 18, 2026
10.0
ui ·
CVE-2026-34909 —
CVE-2026-34909: A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a
KEV
EXPLOITED
PATCHED
unifi_os_server
· CVSS 10.0
· CWE-22
92
5 art.
0
May 22, 2026
9.8
geoserver ·
CVE-2024-36401 —
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Executio
KEV
EXPLOITED
PATCHED
geoserver
· CVSS 9.8
· CWE-95
84
1 art.
0
Jul 1, 2024
8.6
igniterealtime ·
CVE-2023-32315 —
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setu
KEV
EXPLOITED
PATCHED
openfire
· CVSS 8.6
· CWE-22
82
1 art.
0
May 26, 2023
7.1
mappress ·
CVE-2026-56011 —
WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability
KEV
EXPLOITED
mappress maps for wordpress
· CVSS 7.1
· CWE-79
81
1 art.
0
Jun 26, 2026
9.2
libssh2 ·
CVE-2026-55200 —
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
EXPLOITED
PATCHED
libssh2
· CVSS 9.2
· CWE-680
74
8 art.
0
Jun 17, 2026
7.8
cis ·
CVE-2026-20245 —
Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability
EXPLOITED
PATCHED
catalyst_sd-wan_manager
· CVSS 7.8
· CWE-116
74
21 art.
0
Jun 4, 2026
7.1
linux ·
CVE-2026-46333 —
ptrace: slightly saner 'get_dumpable()' logic
EXPLOITED
PATCHED
kernel
· CVSS 7.1
· CWE-362
74
19 art.
0
May 15, 2026
8.6
cis ·
CVE-2026-20230 —
CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma
EXPLOITED
PATCHED
unified_communications_manager
· CVSS 8.6
· CWE-918
74
19 art.
0
Jun 3, 2026
9.9
langflow ·
CVE-2026-55255 —
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
KEV
EXPLOITED
PATCHED
langflow
· CVSS 9.9
· CWE-639
69
2 art.
0
Jun 19, 2026
7.5
gpac project ·
CVE-2025-60474 —
CVE-2025-60474: A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo
EXPLOITED
mp4box
· CVSS 7.5
68
2 art.
0
Jun 24, 2026
8.8
google ·
CVE-2026-13033 —
CVE-2026-13033: Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker
EXPLOITED
PATCHED
chrome
· CVSS 8.8
· CWE-125
65
5 art.
0
Jun 24, 2026
8.8
google ·
CVE-2026-13038 —
CVE-2026-13038: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbi
EXPLOITED
PATCHED
chrome
· CVSS 8.8
· CWE-416
65
5 art.
0
Jun 24, 2026
7.8
linux ·
CVE-2026-46300 —
net: skbuff: preserve shared-frag marker during coalescing
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
64
19 art.
0
May 13, 2026
8.8
google ·
CVE-2026-13036 —
CVE-2026-13036: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code ins
EXPLOITED
PATCHED
chrome
· CVSS 8.8
· CWE-416
62
4 art.
0
Jun 24, 2026
Load more